Data Backup

A mission's ability to recover from a cyber incident, hardware failure, or adversary action depends directly on the availability of verified, uncorrupted backups of critical data that are stored independently from the primary systems those backups are intended to restore. Data backup procedures must be defined within a broader disaster recovery plan that specifies what data is backed up, at what frequency, through what process, and under what conditions restoration will be initiated. At least one recoverable backup copy must be stored outside the primary system’s administrative and failure domains and protected so that compromise of ordinary production systems, credentials, or management services does not provide the ability to modify or destroy that copy. Separation may use offline media, physically separate infrastructure, isolated storage systems, separate cloud accounts or security domains, immutable retention controls, or an approved combination of these mechanisms. Backup storage must be protected against the methods adversaries commonly use to target recovery capability, including ransomware that encrypts or deletes backup repositories, credential attacks against backup management systems, and physical access to backup media. Backup integrity must be verifiable, as a backup that has been silently corrupted or tampered with provides no recovery capability when needed.

Sources

ID: CM0056
Tier: II
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate a documented data backup and recovery plan as a program deliverable, covering the identification of critical data subject to backup, backup frequency and retention periods, off-system storage requirements, backup integrity verification procedures, and the conditions and procedures for initiating restoration. Requirements should specify that at least one recoverable backup copy be isolated from the primary system’s administrative and failure domains so that compromise of production accounts, systems, or management services does not provide access sufficient to alter or destroy that copy. The separation and recovery architecture must be documented and subject to government review. Contract language should require that backup and recovery procedures be tested at defined intervals, including restoration exercises that demonstrate the ability to recover critical data from backups within mission-defined recovery time objectives, with test results submitted as controlled deliverables. Evaluation criteria should assess offerors' proposed backup architecture, their approach to backup protection against adversarial destruction, and their demonstrated experience designing and testing disaster recovery capabilities for mission-critical systems. Verification should include demonstration of a successful restoration exercise before the system is authorized for operations, confirming that backup procedures work as designed and that recovery time objectives can be met.

Pre-Operations Developer/Supplier

Backup architecture design must identify the software, firmware, configuration baselines, command and mission databases, operational records, security documentation, logs, and other data required to restore critical mission functions. Backup frequency, retention, versioning, and protection must be based on the recovery point, recovery time, legal, operational, and security requirements for each category. Cryptographic keys, credentials, and other authenticator material must be backed up only when authorized by the applicable key-management or authenticator-recovery policy and must use protections appropriate to the material. Backup storage and management functions must be administratively separated from the primary environment. Production administrator credentials must not automatically provide authority to modify backup retention, delete recovery copies, or administer the isolated backup environment. Backup access must use separately managed identities, least privilege, strong authentication, restricted management paths, and independent authorization for security-critical deletion or retention changes where warranted. Backup media and storage systems should be protected against ransomware and destructive malware through immutability controls, such as write-once storage or append-only backup repositories, that prevent an adversary with access to the backup system from modifying or deleting existing backup content. Backup integrity verification must be built into the backup process itself, using cryptographic hashes, digital signatures, message authentication codes, or equivalent mechanisms to verify that each backup was completed correctly and that the stored data matches the source at the time of backup, with verification records retained separately from the backup data. Restoration procedures must be documented and tested at mission-defined intervals. Testing must verify media readability and data integrity and demonstrate restoration of representative system functions, required dependencies, access controls, configuration state, and operational interfaces. Periodic exercises should also validate that restored data represents an approved recovery point and can be used without reintroducing the condition that caused the loss.